← all repositories
Puliczek/awesome-mcp-security

Tracking every MCP security paper, panic, and patch

A curated index of the papers, exploits, and advisories showing how Model Context Protocol's convenience is currently outpacing its security.

720 stars Other AI
awesome-mcp-security
Not currently ranked — collecting fresh signals.
star history

What it does This repository is a curated awesome-list that corrals research papers, vulnerability write-ups, videos, and official specification notes about Model Context Protocol (MCP) security. It serves as a centralized index for a protocol whose threat model is still being written, covering everything from ANSI terminal deception to remote code execution in popular servers.

The interesting bit The list captures a protocol in the awkward adolescent phase of its security lifecycle: the official auth specification is actively being rewritten, and the entries read like a live incident feed. Its value is timing—aggregating real-world exploits like the Anthropic Slack server data exfiltration and the mcp-remote RCE alongside academic papers before they disappear into the arXiv void.

Key highlights

  • Aggregates official MCP security considerations from the 2025-03-26 specification, including mandatory input validation and human-in-the-loop requirements.
  • Links to seven recent academic papers systematically analyzing MCP attack vectors, tool poisoning, and enterprise mitigation strategies.
  • Catalogs practical vulnerability reports, including exploits against Cursor, GitHub MCP, WhatsApp MCP, and the Neon official remote server.
  • Collects tooling and code repositories aimed at securing or auditing MCP implementations.
  • Tracks the ongoing replacement of the current MCP authorization specification via GitHub pull requests and community RFCs.

Caveats

  • It is a reading list, not a security framework; you will find links and guidance, not patches or scanners.
  • The README explicitly notes that the official MCP auth specification is currently in flux and may change significantly.

Verdict Worth bookmarking if you are building or auditing MCP servers and need to stay ahead of the vulnerability curve. Skip it if you are looking for a drop-in security tool or a finished standard.

Frequently asked

What is Puliczek/awesome-mcp-security?
A curated index of the papers, exploits, and advisories showing how Model Context Protocol's convenience is currently outpacing its security.
Is awesome-mcp-security open source?
Yes — Puliczek/awesome-mcp-security is an open-source project tracked on heatdrop.
How popular is awesome-mcp-security?
Puliczek/awesome-mcp-security has 720 stars on GitHub.
Where can I find awesome-mcp-security?
Puliczek/awesome-mcp-security is on GitHub at https://github.com/Puliczek/awesome-mcp-security.

heatdrop uses Google Analytics to see which pages get read — nothing else. Your call. How we handle data.